CISA Contraction Raises Questions About the Future of Public-Private Cyber Defense
Aaron Warner, CEO of ProCircular, discusses how shrinking capacity at CISA is shifting more cyber incident response responsibilities to private security firms. He warns that reduced federal collaboration could weaken early threat intelligence sharing, increasing systemic risk across ransomware, supply-chain attacks, and broader enterprise security operations.
Transcript
Hi, everyone. Welcome back here to Text Drug tv. I'm really happy to introduce you to my next guest.
It's his first time on. We had a great conversation off camera. I think it's gonna be a great conversation on here as well.
His name is Aaron Warner. Aaron is the CEO of a company called Pro Circular and a Aaron Welcome. Welcome.
You text Rock. Thank you, Alan. Excited, excited to talk to you.
Lots to talk about. Yes, we do. But you know what, before we talk about all that, I wanted to talk about you a minute.
As I told you, our audience likes to know who, who's talking to them. How did they get to this chair? Like, uh, why did Alan have 'em on?
So, tell, tell us about Aaron. Like, uh, like a lot of CEOs, uh, and people in the tech community, I am racked with imposter syndrome. Uh, so, uh, all of this is, you know, a little bit uncomfortable.
But I, I have enjoyed technology since being the kid that took the TV apart. Um, I, uh, I spent 22 years in biotech, uh, as a CIO and helped to build a really great company from don't cash your check on Friday to, you know, a global player. We had facilities all over the world, um, thousands of employees, and they played a huge role in, uh, life sciences and r and d.
Um, it's an interesting perspective, partially because, uh, like a lot of companies, I started pro circular out of frustration. Um, 20 15, 20 16. I could go to any of the big four and get a enterprise risk assessment, and it was like three quarters of a million dollars.
And, uh, you know, we were doing 180 million in revenue. It's a good firm, right? But just too expensive.
And frankly, with the folks that they were sending to me at the time, I'll leave the vendor out, but my team was running circles around these guys. So, you know, 40 something just finished my MBA. I thought, you know, worst case scenario, if I really screw this up, I can go get a Joby job again.
And, uh, but I, I haven't looked back. Um, biotech was a really interesting intro to cybersecurity, but we have been neck deep in it for a decade now. Uh, at, at Pro Circular.
It's been quite a ride. Absolutely. You know, I, I've been in cyber myself 20, almost 25 years.
25 years. That's 2026. Um, and I was doing, well, we didn't call it cyber, of course then, right?
We called it InfoSec, but was doing Information assurance, Right? Yeah. I was doing it before 2001, even though two, Aaron, I got one question for you.
When you're taking apart the TVs, was it tubes or solid state, Uh, tubes. And in fact, this is really gonna date me. My best friend's dad was an engineer for at t or for Ma Bell.
And my first, uh, foray into computing was to get these card reader machines up and running uhhuh flip the cards. I, we were so young, we pulled the vacuum tubes out and had fights with them after. Oh, God.
All right. Yes, I do remember those. So, but that was when I was in school.
That was your computer class was punch cards, and it was, yeah, a lot of, we used to throw the cards around and then tried to get 'em back in that, right. Oh, God. Yeah.
The box do like this and make yeah. Make 'em, you know, holding it so they'd fit in the what a painting. Anyway, um, it, it's, we've Come a long way.
Yes, we have. And here we are where AI does that for us. But anyway, um, let's talk about pro, pro Circular.
You said you, you know, 10 years on this journey, you know, tell for them. There are people out here who don't know pro circular, that's an overnight sensation to them, Right? We, we, we take a different approach to things.
I was, you know, I, I was a customer of all of these things for a long time. So I have a long list of frustrations with cyber in general, and I just, how would, if I had to sum it up, I'd say that the biggest difference is that pro circular is about people. And everybody says that on their masthead, and it's in their core values and all of those things.
Mm-hmm. But, um, when we look at cybersecurity, we think about people, process and tech, right? Tech is a third of the equation.
And I think most people in cyber feel like it's two thirds at least. And that many or most, or sometimes all of the problems are solvable by tools. Um, I love tools.
I'm a huge practitioner of ai. I've been doing development since forever. Um, but it's about people.
At the end of the day, people make decisions, uh, about budgeting. People make decisions about hardware or software, what your stack looks like or how you approach cybersecurity. People are the ones that click the thing that comes in that it should have protected them from in the first place, right?
That's not, the user is a victim in most cases. And I think we as an industry lose sight of that. Um, I worked in a world where my worst user, this idiot that kept clicking things had an MD PhD from Harvard and, uh, Caltech, uh, really?
Yeah, a total idiot, right? But he kept clicking things and the department would complain about him endlessly. Like, this guy, what the hell is wrong with him?
Like, you mean the MD or the PhD? Like, this is not an idiot. This is a guy that's targeted and it really is a victim of the shortcomings of my security program and the IT program.
So pro circular was kind of a response to that. Like, look, we need to take this problem seriously, but we can't just be a hammer looking for a nail. People are the ones that make decisions here.
How they do things flow over into process. And the tech is to a certain degree, a byproduct of all of the intentions of everybody involved. So I know that everybody says this, that people are important and, and so forth, but I, as a client in cybersecurity, often felt like we were treated like bugs and, um, you know, something to be studied and measured and sort of looked down upon.
We don't take that approach. It it, it was frustrating to me as a customer. We don't do it to our clients.
So if there was really one big difference, um, we have, uh, we've really tried to push home. It's the, the people connection. Um, we, we have some of the best pen testers and offensive and defensive engineers in the world, and none of that means a thing if they can't explain why.
Like, why did you run this pen test? It's great that you cracked us open. Um, what does that mean to me?
Like as a bank or as an insurance firm or a house? Oh, no, it's the risk. Yeah.
What am I talking about here? 'cause it's a cyber's a great hole that you could throw money into, but what actually makes a difference, and our experience is that that's often a people related thing. So we, we focus a lot on the why not so much the how, the, how frankly.
Uh, we're using AI at every turn to try and get rid of as much of that as, as we can so that humans spend their time on analysis, uh, and measurement and comparisons as opposed to data collection. Um, you know, absolutely nothing new in in any of that. I think you can hear, you know, echoes of those sentiments elsewhere.
But we've really tried to sort of focus it in a, a pro circular. We're very good with the technical part of it, but we understand that the, the important part is that there are humans involved in this that aren't technical. So, you know, our job is to engage, help 'em understand why, help 'em to understand what are, what are we trying to accomplish here?
Um, you know, a Alan, one of the first things we do in an engagement with a client, uh, is a SWOT analysis of the company. Um, it's not meant to be like a, yeah, it's not meant to be like a, a a, a proxy for a full enterprise assessment, but it forces the people in the room. And we try to get HR and GC and, you know, all of the sort of stakeholders from the organization, not just it, um, together we talk about what are the goals of this organization, if it's a nonprofit, like who do you serve?
What good are you trying to do? And then we weave that into the security program as opposed to just assuming that this client is the same as all other clients. And, you know, it's about the border and it's about email, and it's about all of the standard things that, that anybody can look into.
We really like to understand who we work with, 'cause it enables us to, to, um, to answer the call better. Big problem or small problem. So, excellent.
That's the long and the short of it, Alan. I, I hope that, I hope that helps house. Yeah, No, it did.
Just one quick thing and we'll get it outta the way in case I forget later. For people who want more information on Pro Circular, what's the website? com.
Excellent. Alright, Aaron, I wanted to talk to you about what we have as our topic of discussion today. You know, I think it was last week, or maybe it was the week before already, I wrote an article that, uh, cis a as as well as the NSA and FBI, as it turns out, have withdrawn from participation in the RSAC conference, biggest security conference in the world, where historically it was a great place for private industry and government and, you know, the, the, the cybersecurity industry to collaborate.
And really, that's sort of the, the second shoe dropping. The first shoe was, I don't wanna call it the gutting of csa, but let's say that they've radically changed the mission of csa. Yep.
Um, you know, they did gut the budget by a lot, and that money that You're using the right words. I i I mean, it was when you Million also changed the mission million. Yeah, absolutely.
And, you know, but the mission has changed where, you know, I, I actually, I look, I know Chris Krebs, I never met Jen Easterly, but I admired her, you know, work from afar. They, they really, I, Alan Friedman, you know, SBOs from csaw, and I knew a lot of people there, and I admired their work because of their ability to bring a public private consortium to bear on our critical infrastructure needs in this country, understanding that whatever it is, 65, 70 5% of our critical infrastructure is not actually run by the government. It's private industries, private companies that are, you know, managing this critical infrastructure.
And, you know, like Jack Nicholson in, in, uh, he walks the wall and we sleep under the, and a few good men, we sleep under. You can't handle the truth. Yeah, You can't.
Exactly. Right. But we sleep under the blanket of their security that they provide.
I worry at night about, right, this public private partnership is kind of, is disappearing is the mission. Who's responsible for this anymore? You know, can we leave it just to private companies?
Do we need a, some sort of community like an RSAC or someone to kind of try to bring it together? I, I don't know what the answer is. If I did, I would say so, but Aaron, what, what are you seeing, or what do you think?
We, We have very similar concerns, Alan, and, um, you know, from the top all, all the way down. Um, normally I avoid politics like the plague, right? That is not a, as most of us try.
Yeah. It's not often a, uh, an a helpful part of a discussion around risk and cybersecurity and so forth. How, however, in, in this case, so much of this is, and I'll be polite, we'll call it political volatility, right?
Mm-hmm. So much of this upheaval and change is having a very real impact on small companies and large companies alike. Um, one of the more telling, I think, concerns I have, and this is where we get into the political part of it, um, I'll read you something real quick.
Heritage Foundation. So everybody talks about this project 2025. Mm-hmm.
Check this out. CISA is a DS component that the left has weaponized to censor speech and affect elections at the expense of securing cyber domain and critical infrastructure. So, Alan, you and I travel in similar circles, right?
And, um, I have never heard a single member of any part of the CISA organization talk to me about censorship. Talk to me about elections. Talk to me about anything other than trying to be that last mile for small businesses in this country when it comes to cyber protection, right?
So there is this assumption for whatever reason, and I'm neither defending it, nor supporting it, but there's this assumption by a lot of people who are making decisions right now that CISA is some sort of a political organization, and that they are spreading what they believe to be disinformation. That has not been my experience at all. And, um, as a result of that, you see all kinds of changes within that organization.
Um, the fact of the matter is, you know, when cyber became started to become a word that you saw in the news, like 20 16, 20 17, the Hillary's emails, like that's where that all started, right? Um, everybody was sort of rushing to get their piece. Everybody in federal government was rushing.
So you had FBI, you had National Guard show up to the party, you had all these TLAs that had been involved, usually outward facing, you mentioned the, the NSA, um, FBI was involved. The, and CISA was sort of the trying to fit into that equation. But at the end of the day, you have the FBI, which is largely responsible for prosecutions.
Like they are cops, they catch bad guys. Mm-hmm. Proactive is not their thing, but never has been.
Right. That, that, and that, that makes perfect sense. Um, I wouldn't want the FBI going around all day looking for crimes they thought might happen, right?
Like, let's stick to investigation National Guard sounds like what it is, which is, you know, critical infrastructure protection and, but largely around government historically. Uh, unless there's a huge disaster. So again, kind of disaster oriented groups.
CISA was going to be, or my conception of it was that CISA was going to be that connection, uh, between where private industry protected medium sized companies and large companies, companies like Pro Circular, uh, protect banks and hospitals, and all of those folks who have enough revenue that they can afford to do something about it. The hope was that CL would be the glue that connected all of us in industry and all of us in, in federal government, and use that to protect that last mile that, um, small Walgreens or, or, uh, a corner shop that has 10 employees. Like those are the guys that are getting killed out there.
Not Dell Dell's gonna be fine, Amazon's gonna be fine, but that plumbing supply company, they're in serious trouble and they, you know, they're a threat to the rest of us as well. So the hope, absolutely, the hope was that CISO could be this answer. The federal government's answer to protecting private industry, and it's been completely changed, and it's left a huge vacuum.
Like I don't honestly know who's supposed to fill that in. I'm guessing it's private industry. Um, you would think I'd be excited about that, like as a business guy.
But the fact is that some of these organizations, uh, a corner store with three or five employees can't afford what we do. My engineers are very, very bright and not cheap. Right?
Well, Not only, certainly not Aaron. And that's always been a problem. You know, they people, a lot of organizations, you know, live below the cyber poverty line, if you will, can't afford that.
And, um, but, but here's the thing. It also goes, you know, I was a PoliSci major in undergrad, and you know, why, why do humans form governments? Because there are certain functions that a government could do, because it represents the will of the people and the critical mass of the people that no individuals or individual companies alone can do.
Right? And, and things like a common defense, why we have a, you know, department of defense, regardless of what you wanna call it these days, why we have a Department of Defense. Why do we have, you know, basic government functions, is because the government, these are the functions that you need something bigger than the individual to do band, you know, banding together the social contract.
If you want to get back to Locke and Rousseau and, and all of these things, it's a social contract. Yeah. The Wolf Man versus the civilized man, if you remember from school.
But, and then if you, you know, and it, and in today's world, part of that common defense is a defense of our critical infrastructure from cyber attack. And that, so to me, that clearly now make no mistake, it, the irony should not be lost that the Project 25 and Heritage people are calling out CISA for, for election fraud when it was, you know, a form Chris Krebs, it says, was fired for saying there was no fraud in the election. Yeah.
Probably because there was no fraud in the election. Yes. For right.
For spreading di well, more than probably that's pretty clear, you know, spreading disinformation. Well, Jen Easterly would put in something its sister to say, Hey, we're gonna look for DI disinformation, because that's a threat to critical infrastructure. And who's dealing disinformation?
Well, you know, we, we, besides the Russian and Chinese and Iranians and North Koreans and all these other bots and their allies, so the irony should not be lost at what they're blaming CIL for was exactly the thing Csil was defending as part of it, right? It, it's, it's, this is truth speak from 1984 or something. You, you hit a really important point, and I'm so gonna dodge all of those stuff.
No, no, you should. That's why I could say it here and you can't. Um, I'll, so let, I'll put it, let me, let me fast forward.
We're gonna fast forward. Aaron, you said it an in one, your company, any company, bigger company, smaller companies, we can't do this without a partner mm-hmm. In Washington without a partner at, at the state levels, perhaps.
Will we see the states, I mean, that's a logical solution perhaps, is individual states help form that private public partnership, at least at the state level or at the local municipalities. What can we, what can we expect? How do we facilitate It?
I, I think that's a start. I think you hit on a really important topic right after we started the cs A, if nothing else, plays a role in connecting some of those various federal organizations and private industry and private practitioners of cybersecurity. Um, the, uh, the FBI has a huge role to play in that.
I'll give you a really quick firsthand. Um, when we get called out on a, on an incident today, you know, the fifth, 5th of February, 2026, when a client calls us and says, Hey, I have a really bad day. Um, I would like you to come to Atlanta right now.
When we do that, one of the first things that we look for are not just the threat actor that has been visible, but the variety of threat actors that can also be in an environment, right? You've got access brokers who sell keys. I've gotta log in and password to kind of anyone.
So when we get on the steam, yes, we may have a ransomware guy, but we got two or three other people in there. Um, there, there may be PHI theft, there may be credit card theft. All of those things are patterns that we need to recognize really quickly.
So when one of our folks gets on the ground, the way it used to work is that we would get in touch with the bureau, say, hi, this is Aaron. I'm on site at this location. I have this threat actor.
Here's what we think they're doing. Here's what the behavior looks like. Now what do I need to worry about?
People within the FBI are organized in what are called AORs and the specif specific AOR that specializes in that bad guy can tell us all sorts of things that are very helpful to the client. This guy normally ex filtrates data watch for that. It's not just ransomware or this threat actor really likes credit cards.
They don't care about your HR data, so don't worry about that. Those kinds of things, real time inform the approach that we have to incident response when it's difficult to get a call returned from the FBI because those guys have been re-tasked to 50 different things. Um, we have to go online and work with our colleagues at private industry, rely on our, our intelligence feed, but it cuts some really valuable real-time information out.
The person who pays the bill for that is the client, not us, not the FBI, but the person who, their company isn't processing orders or anything like that, right? That they're shut down. That's the net effect of, of all of this.
So cis a at a, at a minimum, we benefit as a community so much from sharing what we see and what we learn. Um, that bad guys have to be right once, we've gotta be right all day long. So co coordination and communication is, is part of how we do that.
So I would love to see things like pulling out of RSA, uh, the, the board that Krebs, uh, built with, with CSA was a great way to get industry and federal to share information to one another. I don't know why you would take that apart and it has a very real, like today effect on on. Yeah.
Well, unfortunately, I, I just pray that we don't all pay a huge price before this gets rectified. Anyway, Aaron, we're about outta time, man. What a great conversation.
I appreciate. I appreciate it. Uh, thank you Alan.
Yeah, Very cool. Come back, keep us posted. Good luck with Pro Circular.
com. You can see the spelling in the bottom third with Aaron's name. Aaron, I don't know if you'll be at RSA this year, but we'll be there live at Broadcast Alley all week.
Maybe stop by and say hello. I will, I will. I'll see you there, Aaron.
Thanks. All righty. Aaron Warner, CEO Pro Circular here on Tech Drug tv.
We'll be back with more in a second.